{"id":"GHSA-73p9-6hrp-8qhr","title":"AIIR verification and policy gates could report success without enforcing the control (fail-open)","summary":"AIIR verification and policy gates could report success without enforcing the control (fail-open)","severity":"medium","cwe":["CWE-347","CWE-636"],"vendor":"aiir","product":"aiir","ecosystem":"pip","affected":["aiir < 1.7.0"],"patched":["aiir 1.7.0"],"published":"2026-08-28","updated":"2026-08-28","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-73p9-6hrp-8qhr","references":[{"url":"https://github.com/invariant-systems-ai/aiir/security/advisories/GHSA-73p9-6hrp-8qhr"},{"url":"https://github.com/advisories/GHSA-73p9-6hrp-8qhr"}],"tags":["ghsa","pip"],"ingestedAt":"2026-08-28T19:24:18.665Z","slug":"GHSA-73p9-6hrp-8qhr","body":"## Overview\n\n### Summary\nSeveral of AIIR's verification and policy paths could return a success/\"verified\" result without actually enforcing the control they represent — they could **fail open** rather than fail closed. For a tool whose purpose is trustworthy verification, a consumer relying on these gates may have treated unverified or non-conforming input as verified.\n\nFound during an internal adversarial hardening review of AIIR (not a third-party audit). All paths are fixed in **1.7.0**.\n\n### Affected paths\n- A `require_signing` policy gate could be satisfied by a forgeable/empty field, so an unsigned or forged-bundle receipt could pass a \"signing required\" check without a valid signature.\n- A CI verification path could report `success` regardless of the underlying verification result.\n- A release-verification gate could advertise policy limits it did not actually enforce.\n- A signature-verification path could be silently skipped for certain input categories, exiting success without verifying.\n\n### Impact\nA consumer relying on these gates (e.g. `require_signing`, release/policy verification, or the CI check) to block unsigned, forged, or non-conforming receipts could have received a false \"verified\"/\"pass\". Exploitation requires reliance on the affected gate; it does not forge valid signatures, nor does it compromise content-addressing or correctly-signed receipts.\n\n### Patches\nFixed in **1.7.0**. Every affected path now fails closed, each with a regression test. Upgrade to `aiir >= 1.7.0`.\n\n### Workarounds\nNone for earlier versions other than upgrading. Full cryptographic Sigstore verification (`pip install aiir[sign]`, `--verify-signature` with `--signer-identity`/`--signer-issuer`) provides defense in depth.\n\n### Scope note\nThis advisory covers code present in released versions (`< 1.7.0`). Separately, an unreleased agent-receipt feature had pre-release forgery findings fixed before it shipped — those were never in a released version and are out of scope.\n\n## Affected packages\n\n- `aiir < 1.7.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `aiir 1.7.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}